logo

CVE-2026-70426: Critical Jenkins RCE Flaw Bypasses Deserialization Filter

ID: 026851a8-7a03-53ed-be8b-12f42d26488b

STIX ID: report--026851a8-7a03-53ed-be8b-12f42d26488b

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Do Son

...
...

Jenkins patched a critical deserialization vulnerability (CVE-2026-70426) that bypasses the JEP-200 class filter in Remoting, allowing attackers with Agent/Connect permission to run code on the controller; the advisory fixes this issue and 22 other flaws (including a path traversal, CVE-2026-70428), lists affected weekly and LTS releases, and recommends immediate updates to fixed versions or applying provided workarounds while reviewing agent permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.